Today's report Older
Source: Security Rabbits
The Rabbit's Foot (TLDR)
Citrix NetScaler Zero-Day Exploited to Deploy Web Shells
Attackers are exploiting CVE-2026-88772 (related to CVE-2026-88771) to gain root access, steal credentials, and move laterally. Apply Citrix's latest patches immediately.
Apple Patches CoreGraphics Zero-Day Under Active Exploitation
CVE-2026-86950 is an out-of-bounds write in CoreGraphics exploited in sophisticated targeted attacks. Update iOS, macOS, and iPadOS to the latest versions.
Critical Unauthenticated RCE in Balbooa Forms for Joomla
Balbooa Forms < 2.4.3.4 allows unauthenticated remote code execution via field shortcode injection. Update to 2.4.3.4 or later immediately.
HPE Networking Instant ON: Unauthenticated Remote Buffer Overflow
A critical buffer overflow allows arbitrary code execution as a privileged user. Apply HPE firmware updates urgently due to widespread deployment.
Star Blizzard Targets 100+ Organizations with Fake Event Invites
Russian state hackers use fake event invitations to deliver a Windows backdoor. Warn users and strengthen email filtering and endpoint detection.
Source: CVE Trend
Trending vulnerability
CVE-2026-88771
Citrix NetScaler ADC and Citrix NetScaler Gateway
    Published:
    Updated:

🥕 🥕 🥕 ⚪ ⚪ ⚪ ⚪ ⚪ ⚪ ⚪
(26%)
Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway..This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading ..
Source: CISA
CISA exploits

Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution.
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.(2026-09-29)
Source: NIST
NIST CVE
Unauthenticated remote code execution via field shortcode injection in Balbooa Forms < 2.4.3.4. Any Joomla site running this popular form builder with the PHP-after-submission action enabled is at immediate risk; update to 2.4.3.4 or later.
Unauthenticated arbitrary file write leading to remote code execution in the gmfeed module for PrestaShop. Attackers can write and execute PHP via feed.php; upgrade to version 2.3.9 immediately.
Missing authentication in the PUT /user/updatePwd endpoint allows unauthenticated attackers to reset any storefront account password and take over accounts. Patch or restrict access to this endpoint immediately.
Unauthenticated remote buffer overflow allowing arbitrary code execution as a privileged user on the underlying OS. Given the widespread deployment of Instant ON APs, apply HPE firmware updates urgently.
The default blockUnsafeOperationsPlugin fails to classify trailer..cmd as unsafe, allowing attacker-controlled config to execute shell commands with Node.js process privileges. Upgrade to simple-git 4.0.1 or later.
parseEnv omits VISUAL from GitEnvKeys, letting attacker-influenced environment values invoke an arbitrary editor and execute code. Upgrade argv-parser to 2.0.1 or later.
Attacker-chosen heap corruption via masked WebSocket frames split across packets, enabling remote code execution or crash in embedded devices. Apply the latest NetX Duo patches from Eclipse ThreadX.
Other software at risk
\\   @socket.io/cluster-engine \\   Akaunting \\   AltumCode 66Uptime \\   Amazon GluonTS \\   Anjvision YSSD-RTMP-H5 \\   Apache DolphinScheduler \\   Apache XmlSchema \\   Arm TrustZone-M \\   Balbooa Forms (Joomla) \\   compress (Go) \\   CTranslate2 \\   Dbit T-CPE301K 4G WiFi minirouter \\   DeepSeek-Reasonix (Reasonix Studio) \\   Dell Secure Connect Gateway (SCG) Policy Manager \\   DetaWix Mobile Web Portal \\   Dockhand \\   Eclipse ThreadX \\   Electron \\   EVbee DC-80 \\   Fumasoft Fumeng Cloud \\   Google Chrome \\   Google MCP Toolbox for Databases \\   HPE Networking Instant ON \\   IBM DataStage on Cloud Pak for Data \\   IBM Guardium Data Protection \\   IBM i \\   Joomla \\   JupyterLab \\   lib0 \\   Liberu CRM \\   libsoup \\   mahonelau kykms \\   Marmite \\   mcp-chrome-bridge \\   Mozilla Firefox \\   Nicotine+ \\   NVIDIA DeepStream \\   Ollama \\   Open GenAI Stack (ogx-ai) \\   OpenSSL \\   psyb0t/docker-mailbox \\   risesoft-y9 WorkFlow-Engine \\   Russh \\   Seeyon A6 \\   SGLang \\   simple-git \\   SurrealDB \\   TeamViewer \\   Tibco Administrator \\   urllib3 \\   VLC media player \\   Weblate \\   Wireshark
News
NeedyMantis Provides Long-Term Access to Compromised Networks
Microsoft observed a China-based actor using a previously unidentified malware framework in targeted intrusions against telcos, universities, medical, and government-related organizations. (darkreading)
24-Year-Old Arrested in Dutch Investigation Into ShinyHunters
Dutch police confirm the arrest of a 24-year-old Amsterdam man as part of an investigation into the ShinyHunters hacking group. Dutch police confirmed this week that a 24-year-old man from Amsterdam was arrested earlier this month as part of an [...] (Security Affairs)
Apple Zero-Day Vulnerability Weaponized in Targeted Attacks
Attackers are exploiting CVE-2026-86950, an out-of-bounds write flaw, in an extremely sophisticated fashion, according to Apple. (darkreading)
Japanese Railway Operators Hit with Weekend Cyber Attacks
Tokyo Metro and Keio have revealed separate cyber-attacks (Unsourced)
Russias Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor
Russian state hackers known as Star Blizzard have been using fake event invitations to trick people into installing a backdoor on their Windows computers, according to Microsoft. The campaigns, aimed at people and organizations tied to Ukraine, [...] (The Hacker News)
South Africa Seeks Help After Cyberattack Targets Air Traffic Control
As aviation infrastructure suffers more cyberattacks, air traffic systems are the latest target, with a ransomware toolkit installed on at least one operational network. (darkreading)
Three Million Affected in Pentagon Personnel Agency Data Breach
Pentagon personnel agency breach exposed data of 3 million people after attackers accessed a file-sharing server for about nine months. The U.S. Defense Manpower Data Center (DMDC), which maintains personnel records for the Department of Defense, is [...] (Security Affairs)
Amazon Bedrock AgentCore Flaws Could Expose AWS Credentials
AWS AgentCore SDK flaws could let attackers run commands in AI sandboxes and reach AWS credentials (Unsourced)
Apple patches CoreGraphics zero-day flaw exploited in attacks
Apple released security updates to fix a zero-day vulnerability exploited in "extremely sophisticated" targeted attacks on iOS devices. [...] (BleepingComputer)
Hackers exploit Citrix NetScaler zero-day to deploy web shells
Cybersecurity firms say attackers exploited the Citrix NetScaler CVE-2026-88772 zero-day to deploy custom web shells and tunneling malware, gain root access, steal credentials, and spread into internal networks. [...] (BleepingComputer)
Source: Ransomware.live
Ransomware attacks
🛡️ Wallstreet
Gibson Area Hospital & Health Services
⚔️ Vexy Ransomware
Groupe Proxitel
🛑 N0n
Precision Facades Ltd
⚔️ m3rx
oterolaw.com  \\ cpacb.com  \\ somasolucoes.com  \\ noonsugar.com  \\ iccsi.com  \\ intense.pl
🦨 lockbit5
camorim.com.br  \\ spg.co.kr
🧬 kairos
Unique Repair Services
🐉 interlock
Tekko Enterprises, Inc
⚠️ incransom
bcx.co.za
🦠 Gammax
AHeadStart Tutoring  \\ Crowder Industries, Inc
👿 emperador
Polikem
🧟 chaos
advantech.com  \\ carolinaasthma.com
👹 BrainCipher
trailerbridge.com  \\ wildmanbg.com  \\ northeastrehab.com  \\ mulholland.com  \\ mccordclaims.com  \\ maxwell-group.com  \\ latitudesubro.com  \\ goriteway.com
💻 AuditTeam
Paid Victim 32373FFB7AF7E725